How To: Add and Map Firewall Credentials

How To: Add and Map Firewall Credentials

 


Overview

In this how-to, we will cover the process of adding firewall credentials to a company for firewall scanning.


How To


🔐 Supported Firewall Integrations

ConnectSecure integrates with industry-leading firewalls to enhance visibility and streamline threat detection.
The following models are currently supported:

🧱 Vendors & Models

  • Arista

  • Aruba

  • Cisco ASA

  • Draytek

  • Firewalla

  • Fortigate

  • LANCOM

  • MikroTik

  • OPNsense

  • PaloAlto

  • pfSense

  • SonicWall TZ

  • Sophos UTM

  • Sophos XG / Sophos XGS

  • Ubiquiti_Edgerouter

  • Ubiquiti UDM Pro

  • WatchGuard

  • Zyxel

  • Zyxel ATP

  • Zyxel USGFLEX

Supported Cisco ASA Platforms

Cisco ASA 5506-X, 5508-X, 5512-X, 5515-X, 5516-X, 5525-X, 5545-X, 5555-X, and 5585-X

Cisco ASAv (Virtual ASA)

Cisco Firepower 1000, 2100, 4100, and 9300 series running ASA software

Cisco ASA 5506 The user account used for ConnectSecure firewall scanning must have Privilege Level 15. This is required because the firewall scan executes configuration‑level commands on Cisco ASA devices, and those commands require Level 15 by default.

SSH into SonicWall NSv (Virtual Console / CLI) with Microsoft Azure

If you are using this virtual firewall setup from SonicWall and Azure, you will need to use the original admin login for SSH based credentials to authenticate

Prerequisites

  1. Firewall Host Name or IP

  2. Remote Access Port (HTTPS or SSH)

  3. Username and Password

  4. API Key(s) - some of the integrations will require this, and some will not

Some Firewalls Require Additional Configuration directly in the Firewall Settings.

Fortinet/FortiGate - https://cybercns.atlassian.net/wiki/x/uYAKi

Sophos XG - https://cybercns.atlassian.net/wiki/x/8gAKi


Adding Firewall Credentials

  1. Select any company from the selector.

image-20240229-163531.png
  1. Click on the Overview/Agents > Discovery settings menu:

image-20240422-210808.png

 

  1. Tap on the Add button under the Credentials section.

image-20240422-210855.png
  1. Give the credentials a name, select OS Type of Firewall OS, Credential Type of Firewall Credential; then you can select from the populated list of Firewall Types.

image-20240229-164128.png

Each firewall type will require it’s own unique authentication parameters; please select from the list and provide the required fields.

ConnectSecure supports one firewall network mapping per credential per company.

To map an additional firewall network within the same company, add the same firewall credentials again as a separate set of credential, then use that new entry to map the asset to the another network.

Aruba Firewall assets will not appear under the “Firewall” asset category.
They will continue to be listed under “All Assets” in the portal.


Mapping Firewall Credentials

After creating your firewall credentials, you must associate them with one of your available Probe agents to utilize them during a firewall scan.

  1. Navigate to Overview/Agents > Discovery:

image-20240422-210925.png
  1. Navigate to Probe Agents, then tap the three-dot Action menu.

image-20240422-211029.png
  1. Select the Map Discovery & Credentials option.

image-20240422-211050.png
  1. Under the Credentials drop-down, select the firewall credentials previously configured.

image-20240229-165802.png
  1. Tap on Save to complete, or Cancel to back out with no changes.


Validating Firewall Credentials

Once your Firewall Credentials are configured in Discovery Settings and mapped to the correct Probe Agent, the next step is to validate them.

To do this, go to the Company Overview, open the Probe Agent section, and select the agent’s three‑dot action menu. Choose Scan > Validate Credential Scan > Select the Credentials you would like to validate against > Tap Scan.

image-20260225-163450.png
image-20260225-163639.png
image-20260622-115326.png

After triggering the Credential Validation Scan, you can monitor its progress in the Jobs section of the Portal.

image-20260225-163751.png

Select the date and timestamp of the Validate Credential Scan to view detailed progress.

image-20260225-163856.png

When the scan completes, return to Discovery Settings > Credentials to check the result. A green checkmark indicates the credentials validated successfully, while a red X means validation failed.

image-20260225-163953.png

Run Firewall Scan

To run a firewall scan, you must first have the credentials created and mapped as described above.

  1. Navigate to the Overview > Agents >Probe Agents menu and tap on the three-dot Action menu.

image-20240422-211215.png
  1. Tap the Scan option.

image-20240422-211233.png
  1. Select the Firewall Scan option.

image-20240422-211304.png

Check out https://cybercns.atlassian.net/wiki/x/aIFTjw page for additional details on firewall assets.


Need Support?

If you need assistance, our support team is here to help. You can create, view, and manage support tickets through our portal at any time.

Support Portal: https://connectsecure.freshdesk.com
Email: support@connectsecure.com